Hippoo Mobile App For WooCommerce - Path Traversal (CVE-2025-13339)
Description
The Hippoo Mobile App For WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
psychologyCrowdSec Analysis
CVE-2025-13339 is a path traversal vulnerability in the Hippoo Mobile App For WooCommerce plugin for WordPress, affecting all versions up to and including 1.7.1. This flaw allows unauthenticated attackers to read arbitrary files on the server via the template_redirect() function, potentially exposing sensitive information such as configuration files, credentials, or user data.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2025-13339 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. CrowdSec data also reveals a clear uptick in attacks involving CVE-2025-13339 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.
Attackers exploit this vulnerability by sending requests with the hippoo_serve query parameter containing directory traversal sequences (e.g., ../) to WordPress endpoints, such as /?hippoo_serve=../../../../wp-config.php, in order to read arbitrary files from the server.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2025-12-10 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-08-19 |